GHSA-mhgx-w3w5-2rvcCritical· 10.0▾ MidnightDuplicate Advisory: PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-2xv2-w8cq-5gxw. This link is maintained to preserve external references.
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
praisonai <= 1.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-qpq9-hwx9-cwgcHigh· 7.8Duplicate Advisory: PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-61433High· 7.8PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
CVE-2026-62176Critical· 9.1PraisonAI is a multi-agent teams system
CVE-2026-57131Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-61444Critical· 9.1PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization
GHSA-fq2m-6wqh-x44gCritical· 9.8PraisonAI: Jobs API exposes agent-execution endpoints with no authentication